CVE-2026-85014: undici vulnerable to Denial of Service via WebSocketStream unclean close
undici’s WebSocketStream crashes the client process when a WebSocket connection is closed abruptly without a close handshake. On such an unclean close, the internal socket-close handler calls abort() on the writable stream even when the application holds a writer lock. Per the WHATWG Streams standard, aborting a locked stream returns a promise that rejects with a TypeError, and the handler discards that promise. The unobserved rejection surfaces as an unhandledRejection and, under Node.js’s default behavior, terminates the process.
A malicious or compromised WebSocket server can crash a client with a single connection teardown (a TCP reset, a proxy teardown, or a protocol-violating frame). Affected applications are those using the WebSocketStream API and writing through a writer, which is the standard way to write.
All releases from undici 7.0.0 are affected. WebSocketStream was introduced in 7.0.0.
References
- cna.openjsf.org/security-advisories.html
- github.com/advisories/GHSA-rx4f-c7p8-82vq
- github.com/nodejs/undici/commit/1858656ebb1e919311c1f31613dfd581b7214349
- github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7
- github.com/nodejs/undici/releases/tag/v7.29.1
- github.com/nodejs/undici/releases/tag/v8.10.2
- github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq
- nvd.nist.gov/vuln/detail/CVE-2026-85014
Code Behaviors & Features
Detect and mitigate CVE-2026-85014 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →